PT-2026-20988 · Calibre · Calibre
0X5T
·
Publicado
2026-02-20
·
Atualizado
2026-04-21
·
CVE-2026-26064
CVSS v4.0
9.3
Crítica
| Vetor | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
calibre versions 9.2.1 and below
Description
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. A Path Traversal flaw exists in versions 9.2.1 and below, allowing arbitrary file writes where the user has write permissions. On Windows systems, this can lead to Remote Code Execution by writing a malicious payload to the Startup folder, which is then executed upon the next user login. The
extract pictures function only verifies that file names start with 'Pictures' and does not properly sanitize '..' sequences. While calibre's ZipFile.extractall() function in utils/zipfile.py sanitizes '..' using get targetpath(), the extract pictures() function bypasses this protection by using manual zf.read() and open() operations.Recommendations
Update to calibre version 9.3.0 or later.
Exploit
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Calibre